Apache Tomcat 4.0.5 and earlier, when using both the invoker servlet and the default servlet, allows remote attackers to read source code for server files or bypass certain protections, a variant of CAN-2002-1148.
{
"severity": "HIGH",
"nvd_published_at": "2003-01-17T05:00:00Z",
"github_reviewed_at": "2024-02-12T19:58:01Z",
"github_reviewed": true,
"cwe_ids": [
"CWE-200"
]
}